Junglewise Threat Intelligence

CVE-2026-11166: Google Chrome UXSS in SVG implementation

CVE-2026-11166 · Severity: info · CVSS 6.1 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's handling of SVG images could allow a malicious website to execute scripts in the context of other sites. This type of attack, known as Universal Cross-Site Scripting (UXSS), can lead to the unauthorized access of sensitive user data or the hijacking of user sessions across different web domains. Users are advised to update their browser to the latest version to mitigate this risk.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in the SVG implementation of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly isolate or sanitize SVG content, allowing a remote attacker to bypass the Same-Origin Policy (SOP). By tricking a user into visiting a specially crafted HTML page, an attacker can execute arbitrary JavaScript or HTML in the context of any website the user is currently visiting. This issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats